# Email deliverability best practices

> A practical checklist for reaching the inbox: authentication and DMARC alignment, consent, unsubscribes, list hygiene, content and Gmail and Yahoo sender rules.

This guide collects the practices that matter most for inbox placement and shows how to apply each one with Emailit. Work through it when you set up a new domain, and come back to it when your bounce or complaint rates climb.

## Authenticate everything

Emailit handles SPF and DKIM for you once your domain is verified. Add DMARC yourself.

1. **Verify every domain you send from.** Each subdomain is separate. See [Add a domain](/docs/domains/add-a-domain/).

2. **Publish a DMARC record.** Start with `v=DMARC1; p=none;` on `_dmarc.<domain>`. Gmail, Yahoo and Outlook require DMARC from bulk senders.

3. **Collect DMARC reports.** On Pro and higher, turn on [DMARC reports](/docs/dmarc/set-up/) to see every service that sends as your domain.

4. **Move to enforcement.** Once reports show that all your legitimate mail passes, step up to `p=quarantine` and then `p=reject`. See [Read DMARC reports](/docs/dmarc/reports/#move-to-enforcement).

### How alignment works with Emailit

DMARC passes when SPF or DKIM passes **and** the domain it checked matches your `From` domain.

| Check | Domain checked | Aligned with `From: hello@acme.com`? |
| --- | --- | --- |
| DKIM | `d=acme.com` | Yes, in both relaxed and strict mode. |
| SPF | Return path `emailit.acme.com` | Yes in relaxed mode (the default). No if you set `aspf=s`. |

Leave `aspf` at its default (relaxed). If you need strict alignment, DKIM still aligns, so DMARC keeps passing.

## Separate your mail streams

Use a different subdomain for each kind of mail so that each one builds its own reputation:

| Stream | Example domain | Sent with |
| --- | --- | --- |
| Transactional: receipts, password resets, alerts | `notify.acme.com` | API or SMTP |
| Marketing: newsletters, promotions | `news.acme.com` | Campaigns |

If a campaign draws complaints, your password resets keep landing in the inbox. Pair this with [sending-only API keys](/docs/developers/api-keys/) restricted to one domain, so each app can only send from its own stream.

## Get consent and make leaving easy

- **Only mail people who asked for it.** Don't buy, rent or scrape lists. Cold email isn't allowed on Emailit.
- **Make unsubscribing easy.** Put an unsubscribe link (`{{unsubscribe_url}}`) in every campaign. The campaign's **Send** step flags campaigns without one. Emailit also adds `List-Unsubscribe` and `List-Unsubscribe-Post` headers to campaign emails, so Gmail and Yahoo show their own unsubscribe button and can unsubscribe the recipient in one click.
- **Add the headers to marketing mail you send through the API.** Emailit only adds them to campaigns. For newsletters you send with the API or SMTP, set your own headers:

```json
{
  "headers": {
    "List-Unsubscribe": "<https://acme.com/unsubscribe?u=8f2c>, <mailto:unsubscribe@acme.com>",
    "List-Unsubscribe-Post": "List-Unsubscribe=One-Click"
  }
}
```

  Your URL must accept a `POST` and unsubscribe the person without further steps. See [Headers and metadata](/docs/email-api/headers-and-metadata/).
- **Honor unsubscribes quickly.** Gmail and Yahoo expect requests to take effect within two days. Campaign unsubscribes take effect immediately. For other mail, stop sending as soon as you receive the request, for example by [adding a suppression](/docs/suppressions/manage/).

## Keep your list clean

- **Verify lists you didn't collect yourself,** such as imports from an old system, before the first send. See [Verify a list](/docs/email-verification/lists/).
- **Check addresses at sign-up.** Call [single verification](/docs/email-verification/single/) when someone enters an address, and ask them to fix typos.
- **Keep automatic suppression on.** It stops you from mailing addresses that bounced or complained. See [Suppressions](/docs/suppressions/).
- **Retire inactive recipients.** People who haven't opened or clicked in six months or more drag down engagement. Send them a re-engagement email, then stop mailing those who don't respond.
- **Watch for spikes.** A sudden jump in bounces usually points to one bad list or import. Pause it and investigate before it pushes your workspace into **At risk**.

## Write content that looks like real mail

- **Send a plain-text part** alongside the HTML.
- **Use a consistent sender.** Keep the same `From` name and address for each stream, and use a `Reply-To` that someone reads.
- **Balance images and text.** An email that's a single large image with little text often lands in spam.
- **Link to your own domain.** Avoid URL shorteners and links to domains with a poor reputation.
- **Keep HTML under about 100 KB.** Gmail clips longer messages and hides the rest, including your unsubscribe link. The campaign builder warns you before you send.
- **Avoid attachments in bulk mail.** Link to the file instead. Never attach executables or archives inside archives.
- **Check the score.** Emailit shows the spam checks that fired on every message. See [Spam checks](/docs/deliverability/spam-checks/).

## Meet the bulk sender requirements

Gmail and Yahoo apply these rules to senders of roughly 5,000 or more messages a day to their users, and Outlook.com applies similar ones. They're good practice at any volume.

| Requirement | How it's covered |
| --- | --- |
| SPF and DKIM pass | Automatic once your domain is verified. |
| DMARC record, at least `p=none` | Publish `_dmarc.<domain>`. See [DNS records](/docs/domains/dns-records/#dmarc-txt-optional). |
| `From` domain aligned with SPF or DKIM | Automatic. DKIM always aligns, and SPF aligns in relaxed mode. |
| One-click unsubscribe for marketing mail | Automatic for campaigns. Add the headers yourself for marketing mail sent through the API or SMTP. |
| Visible unsubscribe link in marketing mail | Add `{{unsubscribe_url}}` to every campaign, and a link to your own marketing templates. |
| Unsubscribes honored within two days | Immediate for campaigns. Your responsibility for other mail. |
| Spam complaint rate below 0.3% | Aim for under 0.1%. Watch complaints in [Analytics](/docs/analytics/) and [Google Postmaster Tools](https://postmaster.google.com). |
| TLS for delivery | Emailit delivers over TLS whenever the receiving server supports it. |

## Monitor and react

- **Sending health.** Check your 0–100 score on the **Dashboard**. Act when it drops below 80. See [Sending health](/docs/deliverability/sending-health/).
- **Bounces and complaints.** Use [Analytics](/docs/analytics/) and subscribe to `email.bounced` and `email.complained` [webhooks](/docs/webhooks/event-types/) to react in your app.
- **DMARC reports.** Find services that send as your domain without authentication.
- **Google Postmaster Tools.** Verify your domain there to see the spam rate and reputation Gmail reports for it.

## Related

  - [Bounces and complaints](/docs/deliverability/bounces-and-complaints/): How Emailit handles each kind of failure.
  - [Warm up a domain or IP](/docs/deliverability/warm-up/): Grow volume without tripping filters.

---
Source: https://emailit.com/docs/deliverability/best-practices/
